RE: [suse-security] Re: [Fwd: [suse-security] many nic's]
For example it would be possible to install 4 nics in my box an then use one nic for isp A and one for isp B. Would it be also possible to set up firewalling so that isp A provides internet access to network C and B for network D. Box ISP A (eth0) -----> Network C (eth1) ISP B (eth2) -----> Network D (eth3)
But it should not be possile to access ISP B from Network C and visa verse for ISP A.
This is possible with a 2.4 (or late 2.2?) kernel with the advanced routing options. You need to perform routing based on source address. I expect it to be pretty easy to muddle up in setup and maintenance, so I'd probably advise against it and urge you to set up another box to properly separate both networks. If we're talking about WAN uplinks any old box will be able to handle the traffic easily.
I think it should be possible with the SuSEfirewall. You only have to set up the right routing configuration.
I barely know SuSEFirewall myself, but generic iptables/ipchains aren't your problem. The routing is, as you correctly assume. Cheers, Tobias
participants (1)
-
Reckhard, Tobias